The Social Engineering Personality Framework
| Title | The Social Engineering Personality Framework |
| Publication Type | Conference Paper |
| Year of Publication | 2014 |
| Authors | Uebelacker S., Quiel S. |
| Conference Name | 4th Workshop on Socio-Technical Aspects in Security and Trust (STAST), Vienna, Austria |
| Date Published | July |
| Publisher | IEEE |
| Abstract | We explore ICT security in a socio-technical world and focus in particular on the susceptibility to social engineering attacks. We pursue the question if and how personality traits influence this susceptibility. This allows us to research human factors and their potential impact on the physical and digital security domains. We show how Cialdini's principles of influence can be used to explain why most social engineering attacks succeed and that these attacks mainly rely on peripheral route persuasion. A comprehensive literature review reveals that individual values of a victim's personality traits relate to social engineering susceptibility. Furthermore, we construct suggestions for plausible relations between personality traits of the Five-Factor Model (Big 5) and the principles of influence. Based on these arguments, we propose our "Social Engineering Personality Framework" (SEPF). It supports and guides security researchers in developing holistic detection, mitigation, and prevention strategies while dealing with human factors. |
| DOI | 10.1109/STAST.2014.12 |


